AWS Certified CloudOps Engineer - Associate

Encryption in Transit with ACM

How to get TLS certificates that renew themselves, why some ACM certificates quietly do not, and how to terminate and enforce TLS across load balancers, CloudFront, and S3.

Intermediate 26 minutes 6 Learning Objectives
  1. Describe what ACM manages and where an ACM certificate can and cannot be used
  2. Compare DNS, email, and HTTP domain validation and explain the renewal consequence of each
  3. Determine whether a given certificate is eligible for ACM managed renewal
  4. Select and interpret an ELB security policy for a TLS requirement
  5. Enforce HTTPS end to end across a load balancer, CloudFront, and Amazon S3
  6. Diagnose common certificate request, validation, and renewal failures